Data Security & Privacy
We treat your website data, API credentials, and infrastructure configurations with the highest degree of security. This document outlines our technical safeguards, compliance standards, data handling policies, and incident response procedures.
Last Updated: January 15, 2025Our Security Commitment
At Sitemap.xml, security is engineered into every layer of our platform. We follow industry best practices to ensure confidentiality, integrity, and availability of your data. Our infrastructure is continuously monitored, audited, and hardened against modern threat vectors.
🛡️ Zero Trust Architecture
We operate on a zero-trust model. Every request, regardless of origin, is authenticated, authorized, and encrypted. Internal services communicate over mutually authenticated TLS, and least-privilege access is enforced across all systems.
Technical Safeguards
Encryption Standards
- In Transit: All data communications are secured using TLS 1.3 with perfect forward secrecy (PFS). We enforce HSTS and support modern cipher suites only.
- At Rest: Sensitive data is encrypted using AES-256-GCM. Encryption keys are managed via AWS KMS / GCP Cloud KMS with automatic rotation and strict access controls.
- Secrets Management: API keys, database credentials, and third-party tokens are stored in hardened secret vaults. Never logged, cached, or transmitted in plaintext.
Infrastructure & Network Security
- Multi-region deployment across AWS/GCP with isolated VPCs and private subnets.
- Web Application Firewall (WAF) and DDoS mitigation via Cloudflare/AWS Shield.
- Automated patch management, vulnerability scanning, and container image signing.
- Strict network segmentation; production databases are never publicly routable.
Access Control & Authentication
- Role-Based Access Control (RBAC) with multi-factor authentication (MFA) required for all administrative accounts.
- Service accounts use short-lived, scoped credentials. No permanent static keys.
- Comprehensive audit logging for all user and system actions. Logs are tamper-evident and retained for 365 days.
Data Handling & Lifecycle
We collect and process only the data necessary to deliver sitemap generation, indexing, and analytics services. Below is a breakdown of data categories and our handling procedures:
| Data Category | Examples | Purpose | Retention |
|---|---|---|---|
| Configuration Data | Base URLs, crawl schedules, robots.txt rules | Service delivery & automation | Active account + 30 days post-deletion |
| Generated Sitemaps | XML/HTML output, changelog metadata | Client deployment & search engine submission | Deleted immediately after successful push/cached 7 days |
| Analytics & Telemetry | Crawl stats, indexing success rates, API latency | Performance monitoring & reporting | Aggregated/anonymized; retained for service optimization |
| Billing & Identity | Email, payment tokens, subscription tier | Account management & invoicing | Compliance mandate (min 7 years for financial) |
Data Residency: All data is processed and stored in regions compliant with your account settings. We do not transfer personal data across borders without explicit consent or legal safeguards (SCCs).
Deletion Requests: You may request complete data erasure at any time via the dashboard or by contacting our DPO. Deletion is irreversible and completed within 30 days.
Compliance & Certifications
Sitemap.xml adheres to globally recognized security and privacy frameworks. Our compliance posture is validated through annual third-party audits and continuous monitoring.
- SOC 2 Type II: Independent audit of security, availability, and confidentiality controls. Reports available under NDA.
- ISO 27001: Certified Information Security Management System (ISMS) with risk assessment and treatment processes.
- GDPR & CCPA: Lawful processing bases documented, DSAR workflows automated, and data mapping maintained.
Incident Response & Transparency
We maintain a formal incident response plan aligned with NIST SP 800-61 and ISO 27035. Our security operations center (SOC) monitors threats 24/7.
Response Workflow
- Detection & Triage: Automated alerts from SIEM, WAF, and behavioral analytics.
- Containment & Analysis: Immediate isolation of affected systems. Forensic imaging and root cause analysis.
- Eradication & Recovery: Patch deployment, credential rotation, and service restoration with validation.
- Notification: Affected customers notified within 72 hours if personal data is compromised, per regulatory requirements.
📢 Bug Bounty Program
We encourage responsible disclosure. If you discover a security vulnerability, please report it to security@sitemap.xml. We reward valid reports and commit to transparent communication throughout the remediation process.
Security Contacts & Resources
For technical questions, compliance requests, or security inquiries, use the appropriate channel below:
Data Protection Officer
Security & Vulnerability Reports
Compliance & Audit Requests
PGP Key for encrypted communications: Fingerprint: 4A2B 8C1D 9E0F 7G6H 5I4J 3K2L 1M0N 9O8P